Re: [oe][meta-oe][scarthgap][PATCH 1/1] php: Fix CVE-2024-5458

2024-06-26 Thread Soumya via lists.openembedded.org
lists.openembedded.org Sent: Monday, June 24, 2024 7:59 AM To: openembedded-devel@lists.openembedded.org Subject: [oe][meta-oe][scarthgap][PATCH 1/1] php: Fix CVE-2024-5458 From: Soumya Sambu In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error

[oe][meta-oe][scarthgap][PATCH 1/1] php: Fix CVE-2024-5458

2024-06-23 Thread Soumya via lists.openembedded.org
From: Soumya Sambu In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username +